Encryption
Public and service connections require encrypted transport. Regional object storage enforces server-side encryption and denies non-TLS access.
Trust center
This public overview separates deployed safeguards from account-specific commitments and certifications Routeser does not currently claim.
Public and service connections require encrypted transport. Regional object storage enforces server-side encryption and denies non-TLS access.
Document bytes and extraction job state stay in the selected AWS home region. Tenant policy can constrain eligible regions.
Current production defaults expire raw documents and extraction results after 90 days. Derived artifacts use separate lifecycle policies.
Deletion tombstones job state, removes result fields, and removes current access to the stored raw object; version-aware deletion or lifecycle expiry clears versions.
Routeser avoids logging raw documents or extracted values, and Worker request logging stays off by default. Queue and invocation payloads carry object references, not document bytes.
Tenant API keys are compared as SHA-256 digests. Enterprise workspaces support SSO with optional required-SSO and MFA policies, SCIM provisioning, and role-scoped access.
Who processes data
Vendors that may process customer data to deliver Routeser. Reviewed 2026-07-24.
| Subprocessor | Purpose | Data categories | Scope |
|---|---|---|---|
| Cloudflare | Global edge, public API entry, account and analytics Workers, D1 identity storage, queues, and transactional auth email (magic link, verification, email-change, invitations). | Request metadata, human identity, tenant control-plane state, and auth email recipient addresses and message content. Document bytes are not routed through the edge. | Global edge network and transactional email |
| Amazon Web Services | Regional serverless compute (Lambda), object storage (S3), job state (DynamoDB), and queues (SQS) for document processing. | Uploaded document bytes, rendered pages, extraction job state and results. | us-west-1, ap-south-1 |
| OpenRouter | Model-access gateway that routes extraction requests to the configured model vendors behind a Routeser-owned adapter. | Page content required for extraction and the extraction schema. | Model routing provider |
| Google (Gemini) | Vision-capable extraction model reached through OpenRouter (primary and one fallback route). | Page content required for extraction and the extraction schema. | Model vendor via OpenRouter |
| MiniMax | Vision-capable extraction model reached through OpenRouter (fallback route). | Page content required for extraction and the extraction schema. | Model vendor via OpenRouter |
| Paddle | Merchant of record for subscription billing, checkout, tax handling, and payment processing. | Billing contact and payment details entered at checkout. No document content. | Billing / payments |
Honest assurance
Routeser does not claim SOC 2 certification. Security questionnaires, contractual commitments, and a Data Processing Addendum require review with a Routeser contact.
Regional controls cover document bytes and job state. Human identity, control-plane metadata, analytics archives, and the model providers listed above have distinct boundaries that should be evaluated for your requirements.
Request a DPA. This is a manual request process today, not a self-service acceptance flow.
Questions, answered plainly
No certification is claimed on this site. Ask for the current assurance status during procurement.
Current production defaults set raw document and extraction-result retention to 90 days, with separate shorter policies for derived artifacts.
No. It covers document bytes and extraction job state. Identity, control-plane metadata, analytics, and provider processing have separate boundaries.
Next step
Bring your residency, retention, and assurance requirements to an account-specific review.